• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Suspicious sys0972500-1.php inside httpdocs/

Andrew_Pa

Regular Pleskian
Before 2 days I found inside the httpdocs a new folder which name was css. Inside this folder I found a file named sys0972500-1.php , which it caused send thousands spam emails from my server.

I deleted it and today I had the same problem.

The website I have inside the httpdocs is joomla, which I have updated to the newest version and also I updated the templates.

I also changed the ftp password.

I found on the net another guy with the same problem but he didn't find a solution.

You can find the code which was inside the suspicious file by clicking the link : http://pastebin.com/NbyT5wfF

I have many domains on my Plesk Server, but this "hack" appears only in one of them.

How prevent from writing files on httpdocs?

Also I already changed all the permission of the folder and files (inside httpdocs) from ssh.

Thank you in advance
 
Hi Andrew Pa,

sadly, this is a public bug in Joomla, which is being caused of a sadly written code.
Thus, this is a forum to Parallels products, and I think, no one could give you a shot.

But I can give you some tips:

Change the FTP-Password, upgrade your Joomla asap, and check all added extensions for updates.

We had the same problem, and the bug was in the core of joomla...
If you need assistance, give me a PM.
 
I hope that you have read already this article http://kb.parallels.com/en/114620 and applied all recommendations.

Thank you very much Igor for the suggestions! I read all of them and I try to apply them!

Hi Andrew Pa,

sadly, this is a public bug in Joomla, which is being caused of a sadly written code.
Thus, this is a forum to Parallels products, and I think, no one could give you a shot.

But I can give you some tips:

Change the FTP-Password, upgrade your Joomla asap, and check all added extensions for updates.

We had the same problem, and the bug was in the core of joomla...
If you need assistance, give me a PM.

Thank you so much my friend for the reply! I know that was from joomla but I was need a confirmation. This site isn't mine. But as Administrator of the server I should check why the problem appears.

Thank you very much for your help!
 
Dear Andrew Pa,

but it is your server, thats right? Then you should enable the log to get all php mail() commands to be informed, if another bug is being used.
You can send me an PM at any time, as I will assist you as I can for free.
 
Dear Andrew Pa,

but it is your server, thats right? Then you should enable the log to get all php mail() commands to be informed, if another bug is being used.
You can send me an PM at any time, as I will assist you as I can for free.

I have already disable the php functions for email. I check with a script and you cannot send email from this domain using php. Also I have disabled python and perl and I ave disabled the email. But the domain still send thousand emails because of this script. I think is joomla problem and not server side problem. I sent you PM!

Thank you very very much for one more time!
 
Back
Top